GPU VulnDB

Database/Firmware, BMC & network fabric

Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): TENANT ISOLATION: a VF setting its receive mode causes

CVE-2026-72312Firmware, BMC & network fabriccurated

Impact

TENANT ISOLATION: a VF setting its receive mode causes the *physical function's* promiscuous and all-multicast MCAM rules to be deleted, because the enable/disable APIs operate on the PF even when the request arrives over a VF's mailbox. One tenant's VF can therefore change what the host's own interface receives — either blinding the operator's PF, or, in the inverse direction, the coupling means VF-driven rx-mode changes have effects outside the VF's own scope. On a shared OCTEON adapter that is one tenant reaching across the SR-IOV boundary into the host's receive path.

Who can reach it

A tenant with an assigned OCTEON VF issuing a normal nix_set_rx_mode mailbox request — no exploit primitive needed, just the ordinary API.

What to do

Kernel upgrade plus host reboot across OCTEON-equipped nodes. No config workaround; the coupling is in the mailbox handler. Rolling drain per node.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.